phantom-ai-coworker

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s broad powers match its stated 'AI co-worker' purpose, so it is not clearly deceptive, but its footprint is extremely high risk. Autonomous messaging, self-modification, remote MCP expansion, many credentials, public endpoints, shell/Docker control, and a mounted Docker socket create a powerful agent that could be abused or prompt-injected into impactful actions.

Confidence: 90%Severity: 89%
Audit Metadata
Analyzed At
Mar 31, 2026, 09:01 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fphantom-ai-coworker%2F@2c5819a5d6b4bdd698390eb330f278598f12efc9